Claim() doesn't burn TKN shares
https://github.com/Cyfrin/2023-07-beedle/blob/main/src/Staking.sol#L56
so an attacker can drain all WETH from the contract
POC:
https://gist.github.com/justefg/deb2c1102fd6668405c1ba879567d215
Mitigation Steps:
Burn TKNs
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.